3fa9c69097a8549b572e4f2e5b0e4fb90f8cb607
[akkoma] / lib / pleroma / web / admin_api / admin_api_controller.ex
1 # Pleroma: A lightweight social networking server
2 # Copyright © 2017-2019 Pleroma Authors <https://pleroma.social/>
3 # SPDX-License-Identifier: AGPL-3.0-only
4
5 defmodule Pleroma.Web.AdminAPI.AdminAPIController do
6 use Pleroma.Web, :controller
7 alias Pleroma.User
8 alias Pleroma.Web.ActivityPub.Relay
9 alias Pleroma.Web.AdminAPI.AccountView
10 alias Pleroma.Web.AdminAPI.Search
11
12 import Pleroma.Web.ControllerHelper, only: [json_response: 3]
13
14 require Logger
15
16 @users_page_size 50
17
18 action_fallback(:errors)
19
20 def user_delete(conn, %{"nickname" => nickname}) do
21 User.get_by_nickname(nickname)
22 |> User.delete()
23
24 conn
25 |> json(nickname)
26 end
27
28 def user_create(
29 conn,
30 %{"nickname" => nickname, "email" => email, "password" => password}
31 ) do
32 user_data = %{
33 nickname: nickname,
34 name: nickname,
35 email: email,
36 password: password,
37 password_confirmation: password,
38 bio: "."
39 }
40
41 changeset = User.register_changeset(%User{}, user_data, confirmed: true)
42 {:ok, user} = User.register(changeset)
43
44 conn
45 |> json(user.nickname)
46 end
47
48 def user_toggle_activation(conn, %{"nickname" => nickname}) do
49 user = User.get_by_nickname(nickname)
50
51 {:ok, updated_user} = User.deactivate(user, !user.info.deactivated)
52
53 conn
54 |> json(AccountView.render("show.json", %{user: updated_user}))
55 end
56
57 def tag_users(conn, %{"nicknames" => nicknames, "tags" => tags}) do
58 with {:ok, _} <- User.tag(nicknames, tags),
59 do: json_response(conn, :no_content, "")
60 end
61
62 def untag_users(conn, %{"nicknames" => nicknames, "tags" => tags}) do
63 with {:ok, _} <- User.untag(nicknames, tags),
64 do: json_response(conn, :no_content, "")
65 end
66
67 def list_users(conn, params) do
68 {page, page_size} = page_params(params)
69 filters = maybe_parse_filters(params["filters"])
70
71 search_params = %{
72 query: params["query"],
73 page: page,
74 page_size: page_size
75 }
76
77 with {:ok, users, count} <- Search.user(Map.merge(search_params, filters)),
78 do:
79 conn
80 |> json(
81 AccountView.render("index.json",
82 users: users,
83 count: count,
84 page_size: page_size
85 )
86 )
87 end
88
89 @filters ~w(local external active deactivated)
90
91 defp maybe_parse_filters(filters) when is_nil(filters) or filters == "", do: %{}
92
93 @spec maybe_parse_filters(String.t()) :: %{required(String.t()) => true} | %{}
94 defp maybe_parse_filters(filters) do
95 filters
96 |> String.split(",")
97 |> Enum.filter(&Enum.member?(@filters, &1))
98 |> Enum.map(&String.to_atom(&1))
99 |> Enum.into(%{}, &{&1, true})
100 end
101
102 def right_add(conn, %{"permission_group" => permission_group, "nickname" => nickname})
103 when permission_group in ["moderator", "admin"] do
104 user = User.get_by_nickname(nickname)
105
106 info =
107 %{}
108 |> Map.put("is_" <> permission_group, true)
109
110 info_cng = User.Info.admin_api_update(user.info, info)
111
112 cng =
113 user
114 |> Ecto.Changeset.change()
115 |> Ecto.Changeset.put_embed(:info, info_cng)
116
117 {:ok, _user} = User.update_and_set_cache(cng)
118
119 json(conn, info)
120 end
121
122 def right_add(conn, _) do
123 conn
124 |> put_status(404)
125 |> json(%{error: "No such permission_group"})
126 end
127
128 def right_get(conn, %{"nickname" => nickname}) do
129 user = User.get_by_nickname(nickname)
130
131 conn
132 |> json(%{
133 is_moderator: user.info.is_moderator,
134 is_admin: user.info.is_admin
135 })
136 end
137
138 def right_delete(
139 %{assigns: %{user: %User{:nickname => admin_nickname}}} = conn,
140 %{
141 "permission_group" => permission_group,
142 "nickname" => nickname
143 }
144 )
145 when permission_group in ["moderator", "admin"] do
146 if admin_nickname == nickname do
147 conn
148 |> put_status(403)
149 |> json(%{error: "You can't revoke your own admin status."})
150 else
151 user = User.get_by_nickname(nickname)
152
153 info =
154 %{}
155 |> Map.put("is_" <> permission_group, false)
156
157 info_cng = User.Info.admin_api_update(user.info, info)
158
159 cng =
160 Ecto.Changeset.change(user)
161 |> Ecto.Changeset.put_embed(:info, info_cng)
162
163 {:ok, _user} = User.update_and_set_cache(cng)
164
165 json(conn, info)
166 end
167 end
168
169 def right_delete(conn, _) do
170 conn
171 |> put_status(404)
172 |> json(%{error: "No such permission_group"})
173 end
174
175 def set_activation_status(conn, %{"nickname" => nickname, "status" => status}) do
176 with {:ok, status} <- Ecto.Type.cast(:boolean, status),
177 %User{} = user <- User.get_by_nickname(nickname),
178 {:ok, _} <- User.deactivate(user, !status),
179 do: json_response(conn, :no_content, "")
180 end
181
182 def relay_follow(conn, %{"relay_url" => target}) do
183 with {:ok, _message} <- Relay.follow(target) do
184 json(conn, target)
185 else
186 _ ->
187 conn
188 |> put_status(500)
189 |> json(target)
190 end
191 end
192
193 def relay_unfollow(conn, %{"relay_url" => target}) do
194 with {:ok, _message} <- Relay.unfollow(target) do
195 json(conn, target)
196 else
197 _ ->
198 conn
199 |> put_status(500)
200 |> json(target)
201 end
202 end
203
204 @doc "Sends registration invite via email"
205 def email_invite(%{assigns: %{user: user}} = conn, %{"email" => email} = params) do
206 with true <-
207 Pleroma.Config.get([:instance, :invites_enabled]) &&
208 !Pleroma.Config.get([:instance, :registrations_open]),
209 {:ok, invite_token} <- Pleroma.UserInviteToken.create_token(),
210 email <-
211 Pleroma.UserEmail.user_invitation_email(user, invite_token, email, params["name"]),
212 {:ok, _} <- Pleroma.Mailer.deliver(email) do
213 json_response(conn, :no_content, "")
214 end
215 end
216
217 @doc "Get a account registeration invite token (base64 string)"
218 def get_invite_token(conn, _params) do
219 {:ok, token} = Pleroma.UserInviteToken.create_token()
220
221 conn
222 |> json(token.token)
223 end
224
225 @doc "Get a password reset token (base64 string) for given nickname"
226 def get_password_reset(conn, %{"nickname" => nickname}) do
227 (%User{local: true} = user) = User.get_by_nickname(nickname)
228 {:ok, token} = Pleroma.PasswordResetToken.create_token(user)
229
230 conn
231 |> json(token.token)
232 end
233
234 def errors(conn, {:param_cast, _}) do
235 conn
236 |> put_status(400)
237 |> json("Invalid parameters")
238 end
239
240 def errors(conn, _) do
241 conn
242 |> put_status(500)
243 |> json("Something went wrong")
244 end
245
246 defp page_params(params) do
247 {get_page(params["page"]), get_page_size(params["page_size"])}
248 end
249
250 defp get_page(page_string) when is_nil(page_string), do: 1
251
252 defp get_page(page_string) do
253 case Integer.parse(page_string) do
254 {page, _} -> page
255 :error -> 1
256 end
257 end
258
259 defp get_page_size(page_size_string) when is_nil(page_size_string), do: @users_page_size
260
261 defp get_page_size(page_size_string) do
262 case Integer.parse(page_size_string) do
263 {page_size, _} -> page_size
264 :error -> @users_page_size
265 end
266 end
267 end